First published: Sat Dec 03 2016(Updated: )
Incorrect signature verification
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/simplesamlphp/simplesamlphp-module-infocard | <1.0.1 | |
debian/simplesamlphp | 1.16.3-1+deb10u2 1.16.3-1+deb10u1 1.19.0-1 1.19.7-1 | |
composer/simplesamlphp/simplesamlphp-module-infocard | <1.0.1 | 1.0.1 |
SimpleSAMLphp InfoCard module | =1.0 | |
Debian GNU/Linux | =7.0 | |
Debian GNU/Linux | =8.0 | |
Debian GNU/Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-12874 has a moderate severity level due to its impact on the integrity of XML message signatures.
To mitigate CVE-2017-12874, upgrade to SimpleSAMLphp module InfoCard version 1.0.1 or later.
CVE-2017-12874 affects versions of SimpleSAMLphp module InfoCard prior to 1.0.1.
CVE-2017-12874 is a vulnerability related to incorrect signature verification.
Yes, CVE-2017-12874 allows attackers to spoof XML messages by exploiting the vulnerability in signature validation.